Windows DNS Server Remote Code Execution Vulnerability

MonitorCVSS 6.8CVE-2026-50426Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorAdjacent
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

A path traversal vulnerability in Windows DNS Server allows an authorized attacker with administrative privileges and adjacent network access to execute arbitrary code on the DNS server. The vulnerability exists across Windows Server 2016, 2019, 2022, 2025, and Windows 10 versions 1607 and 1809. Microsoft has released patches for all affected products in the July 2026 security update.

What this means
What could happen
An attacker with adjacent network access and high-level administrative privileges could execute arbitrary code on a Windows DNS server, potentially disrupting name resolution services or gaining control of the server for lateral movement within your network.
Who's at risk
Windows Server administrators responsible for DNS services (Windows Server 2016, 2019, 2022, 2025) and IT staff managing Windows 10 endpoints with DNS Server roles. This affects on-premises DNS infrastructure commonly deployed in utilities for internal name resolution.
How it could be exploited
An attacker on the same network segment (adjacent network) with administrative credentials could exploit a path traversal flaw in the DNS Server service to execute arbitrary code. The attacker would need both network proximity and high-privilege credentials to exploit this vulnerability.
Prerequisites
  • Attacker must have network access to the same network segment as the DNS server (adjacent network)
  • Attacker must have administrator-level credentials on the DNS server or its domain
  • DNS Server service must be running
Requires high-level privileges (administrator)Requires adjacent network accessAffects critical DNS infrastructureLow exploit probability (EPSS 0.4%)
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9339
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict network access to DNS Server to only authorized administrative workstations using firewall rules or network segmentation
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Windows update for July 2026 (or the latest available monthly security update) to all affected Windows Server and Windows 10 systems running DNS Server
Long-term hardening
0/1
HARDENINGAudit DNS Server administrative accounts and enforce strong authentication (such as multi-factor authentication) for any remote administration
API: /api/v1/advisories/0fc6f179-6739-4a32-ad15-f2a774d7eca7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.